Executive brief
A vulnerability in systemd-journald allows a local user to send malicious control codes to the terminal screens of other users, including administrators. This occurs because the system fails to clean up special characters in emergency log messages before broadcasting them to all active users. An attacker could use this to trick an administrator's terminal into executing unauthorized commands or stealing sensitive data if the administrator is using a vulnerable terminal application.
Technical details
systemd-journald in systemd 259 is vulnerable to an injection flaw when 'ForwardToWall=yes' is enabled (often the default). The component fails to sanitize ANSI escape sequences from log messages before broadcasting them via the 'wall' mechanism. A local, unprivileged attacker can use the 'logger -p emerg' command to send crafted messages containing terminal escape sequences. If an administrator or another user is using a terminal emulator vulnerable to escape sequence injection (such as certain versions of XTerm), the attacker can achieve arbitrary code execution or unauthorized file access in the context of that user. Mitigation involves setting 'ForwardToWall=no' in journald.conf.
Affected products
- systemd project systemd 259
Timeline
- 2025-12-23: disclosed: Privately reported to upstream developers
- 2026-04-07: advisory: Public disclosure by researcher
- 2026-04-10: other: CVE assigned